mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-03 06:25:55 +00:00
improvements: address feedback, feature docs and cert validation with dns rebinding handling
This commit is contained in:
@@ -0,0 +1,126 @@
|
||||
---
|
||||
title: "Microsoft SQL Server Connection"
|
||||
description: "Learn how to configure a Microsoft SQL Server Connection for Infisical."
|
||||
---
|
||||
|
||||
Infisical supports connecting to Microsoft SQL Server using database principals.
|
||||
|
||||
## Configure a Microsoft SQL Server Principal for Infisical
|
||||
|
||||
<Steps>
|
||||
<Step title="Create a Principal">
|
||||
Infisical recommends creating a designated server login and database user in your Microsoft SQL Server database for your connection.
|
||||
```SQL
|
||||
-- create server-level login
|
||||
CREATE LOGIN infisical_login WITH PASSWORD = 'my-password';
|
||||
|
||||
-- create database-level user with login from above
|
||||
USE my_database;
|
||||
CREATE USER infisical_user FOR LOGIN infisical_login;
|
||||
GRANT CONNECT TO infisical_user;
|
||||
|
||||
-- If you intend to use Platform Managed Credentials (see below)
|
||||
GRANT ALTER ANY LOGIN TO infisical_login;
|
||||
```
|
||||
</Step>
|
||||
<Step title="Grant Relevant Permissions">
|
||||
Depending on how you intend to use your Microsoft SQL Server connection, you'll need to grant one or more of the following permissions.
|
||||
|
||||
<Tip>
|
||||
To learn more about Microsoft SQL Server's permission system, please visit their [documentation](https://learn.microsoft.com/en-us/sql/t-sql/statements/grant-transact-sql?view=sql-server-ver16).
|
||||
</Tip>
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Secret Rotation">
|
||||
For Secret Rotations, your Infisical user will require the ability to alter other logins' passwords:
|
||||
```SQL
|
||||
GRANT ALTER ANY LOGIN TO infisical_login;
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
</Step>
|
||||
<Step title="Get Connection Details">
|
||||
You'll need the following information to create your Microsoft SQL Server connection:
|
||||
- `host` - The hostname or IP address of your Microsoft SQL Server server
|
||||
- `port` - The port number your Microsoft SQL Server server is listening on (default: 1433)
|
||||
- `database` - The name of the specific database you want to connect to
|
||||
- `username` - The username of the login created in the steps above
|
||||
- `password` - The password of the login created in the steps above
|
||||
- `sslCertificate` (optional) - The SSL certificate required for connection (if configured)
|
||||
</Step>
|
||||
</Steps>
|
||||
|
||||
## Create Connection in Infisical
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
1. Navigate to the App Connections tab on the Organization Settings page.
|
||||

|
||||
|
||||
2. Select the **Microsoft SQL Server Connection** option.
|
||||

|
||||
|
||||
3. Select the **Username & Password** method option and provide the details obtained from the previous section and press **Connect to Microsoft SQL Server**.
|
||||
<Note>
|
||||
Optionally, if you'd like Infisical to manage the credentials of this connection, you can enable the Platform Managed Credentials option.
|
||||
If enabled, Infisical will update the password of the connection on creation to prevent external access to this database role.
|
||||
</Note>
|
||||

|
||||
|
||||
4. Your **Microsoft SQL Server Connection** is now available for use.
|
||||

|
||||
</Tab>
|
||||
<Tab title="API">
|
||||
To create a Microsoft SQL Server Connection, make an API request to the [Create PostreSQL
|
||||
Connection](/api-reference/endpoints/app-connections/mssql/create) API endpoint.
|
||||
|
||||
<Note>
|
||||
Optionally, if you'd like Infisical to manage the credentials of this connection, you can set the `isPlatformManagedCredentials` option to `true`.
|
||||
If enabled, Infisical will update the password of the connection on creation to prevent external access to this database role.
|
||||
</Note>
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://app.infisical.com/api/v1/app-connections/mssql \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"name": "my-mssql-connection",
|
||||
"method": "username-and-password",
|
||||
"isPlatformManagedCredentials": true,
|
||||
"credentials": {
|
||||
"host": "123.4.5.6",
|
||||
"port": 1433,
|
||||
"database": "default",
|
||||
"username": "infisical_login",
|
||||
"password": "my-password",
|
||||
},
|
||||
}'
|
||||
```
|
||||
|
||||
### Sample response
|
||||
|
||||
```bash Response
|
||||
{
|
||||
"appConnection": {
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"name": "my-pg-connection",
|
||||
"version": 1,
|
||||
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"createdAt": "2023-11-07T05:31:56Z",
|
||||
"updatedAt": "2023-11-07T05:31:56Z",
|
||||
"app": "mssql",
|
||||
"method": "username-and-password",
|
||||
"isPlatformManagedCredentials": true,
|
||||
"credentials": {
|
||||
"host": "123.4.5.6",
|
||||
"port": 1433,
|
||||
"database": "default",
|
||||
"username": "infisical_login"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
@@ -74,4 +74,9 @@ in the UI or by passing the associated `connectionId` when generating resources
|
||||
<Note>
|
||||
Infisical is continuously expanding its third-party application support. If your desired application isn't listed,
|
||||
you can still use previous methods of connecting to it such as our Native Integrations.
|
||||
</Note>
|
||||
</Note>
|
||||
|
||||
## Platform Managed Credentials
|
||||
|
||||
Some App Connections support the ability to have their credentials managed by Infisical. By enabling this option,
|
||||
Infisical will modify the credentials to prevent external use of the configured access entity.
|
||||
@@ -0,0 +1,119 @@
|
||||
---
|
||||
title: "PostgreSQL Connection"
|
||||
description: "Learn how to configure a PostgreSQL Connection for Infisical."
|
||||
---
|
||||
|
||||
Infisical supports connecting to PostgreSQL using a database role.
|
||||
|
||||
## Configure a PostgreSQL Role for Infisical
|
||||
|
||||
<Steps>
|
||||
<Step title="Create a Role">
|
||||
Infisical recommends creating a designated role in your PostgreSQL database for your connection.
|
||||
```SQL
|
||||
-- create user role
|
||||
CREATE ROLE infisical_role WITH LOGIN PASSWORD 'my-password'
|
||||
|
||||
-- grant login access to the specified database
|
||||
GRANT CONNECT ON DATABASE my_database TO infisical_role;
|
||||
```
|
||||
</Step>
|
||||
<Step title="Grant Relevant Permissions">
|
||||
Depending on how you intend to use your PostgreSQL connection, you'll need to grant one or more of the following permissions.
|
||||
<Tip>
|
||||
To learn more about PostgreSQL's permission system, please visit their [documentation](https://www.postgresql.org/docs/current/sql-grant.html).
|
||||
</Tip>
|
||||
<Tabs>
|
||||
<Tab title="Secret Rotation">
|
||||
For Secret Rotations, your Infisical user will require the ability to alter other users' passwords:
|
||||
```SQL
|
||||
ALTER ROLE infisical_role WITH CREATEROLE;
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
</Step>
|
||||
<Step title="Get Connection Details">
|
||||
You'll need the following information to create your PostgreSQL connection:
|
||||
- `host` - The hostname or IP address of your PostgreSQL server
|
||||
- `port` - The port number your PostgreSQL server is listening on (default: 5432)
|
||||
- `database` - The name of the specific database you want to connect to
|
||||
- `username` - The role name of the login created in the steps above
|
||||
- `password` - The role password of the login created in the steps above
|
||||
- `sslCertificate` (optional) - The SSL certificate required for connection (if configured)
|
||||
</Step>
|
||||
</Steps>
|
||||
|
||||
## Create Connection in Infisical
|
||||
|
||||
<Tabs>
|
||||
<Tab title="Infisical UI">
|
||||
1. Navigate to the App Connections tab on the Organization Settings page.
|
||||

|
||||
|
||||
2. Select the **PostgreSQL Connection** option.
|
||||

|
||||
|
||||
3. Select the **Username & Password** method option and provide the details obtained from the previous section and press **Connect to PostgreSQL**.
|
||||
<Note>
|
||||
Optionally, if you'd like Infisical to manage the credentials of this connection, you can enable the Platform Managed Credentials option.
|
||||
If enabled, Infisical will update the password of the connection on creation to prevent external access to this database role.
|
||||
</Note>
|
||||

|
||||
|
||||
4. Your **PostgreSQL Connection** is now available for use.
|
||||

|
||||
</Tab>
|
||||
<Tab title="API">
|
||||
To create a PostgreSQL Connection, make an API request to the [Create PostgreSQL
|
||||
Connection](/api-reference/endpoints/app-connections/postgres/create) API endpoint.
|
||||
|
||||
<Note>
|
||||
Optionally, if you'd like Infisical to manage the credentials of this connection, you can set the `isPlatformManagedCredentials` option to `true`.
|
||||
If enabled, Infisical will update the password of the connection on creation to prevent external access to this database role.
|
||||
</Note>
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
curl --request POST \
|
||||
--url https://app.infisical.com/api/v1/app-connections/postgres \
|
||||
--header 'Content-Type: application/json' \
|
||||
--data '{
|
||||
"name": "my-pg-connection",
|
||||
"method": "username-and-password",
|
||||
"isPlatformManagedCredentials": true,
|
||||
"credentials": {
|
||||
"host": "123.4.5.6",
|
||||
"port": 5432,
|
||||
"database": "default",
|
||||
"username": "infisical_role",
|
||||
"password": "my-password",
|
||||
},
|
||||
}'
|
||||
```
|
||||
|
||||
### Sample response
|
||||
|
||||
```bash Response
|
||||
{
|
||||
"appConnection": {
|
||||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"name": "my-pg-connection",
|
||||
"version": 1,
|
||||
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||
"createdAt": "2023-11-07T05:31:56Z",
|
||||
"updatedAt": "2023-11-07T05:31:56Z",
|
||||
"app": "postgres",
|
||||
"method": "username-and-password",
|
||||
"isPlatformManagedCredentials": true,
|
||||
"credentials": {
|
||||
"host": "123.4.5.6",
|
||||
"port": 5432,
|
||||
"database": "default",
|
||||
"username": "infisical_role"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
</Tab>
|
||||
</Tabs>
|
||||
Reference in New Issue
Block a user